Re: Fwd: [golang-dev] [security] Go 1.8.4 and Go 1.9.1 are released

2017-10-09 Thread Ed Marshall
On 10/09/2017 04:36 AM, Jakub Cajka wrote: For record these vulnerabilities got assigned CVE-2017-15041 and CVE-2017-15042. Any packages using the affected component "net/smtp" needs to be rebuild with the fixed version of Go, in order to pick up the fix. Oof. Do we have any tools right now f

Fwd: [golang-dev] [security] Go 1.8.4 and Go 1.9.1 are released

2017-10-09 Thread Jakub Cajka
For record these vulnerabilities got assigned CVE-2017-15041 and CVE-2017-15042. Any packages using the affected component "net/smtp" needs to be rebuild with the fixed version of Go, in order to pick up the fix. Updates has been submitted in to Fedora 26,27,Rawhide(they are not in build root-ov